PT-2003-1258 · Sun · Sun One Starter Kit
Published
2003-03-18
·
Updated
2008-09-05
·
CVE-2002-1525
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Sun ONE Starter Kit version 2.0
Description
A directory traversal issue exists in the ASTAware SearchDisk engine, allowing remote attackers to read arbitrary files. This can be achieved through a .. (dot dot) attack on ports 6015 or 6016, or by using an absolute pathname to access port 6017.
Recommendations
For Sun ONE Starter Kit version 2.0, restrict access to ports 6015, 6016, and 6017 to minimize the risk of exploitation. As a temporary workaround, consider disabling the ASTAware SearchDisk engine until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sun One Starter Kit